CVE-2007-1558

N/A Unknown
Published: April 16, 2007 Modified: April 23, 2026
View on NVD

Description

The APOP protocol allows remote attackers to guess the first 3 characters of a password via man-in-the-middle (MITM) attacks that use crafted message IDs and MD5 collisions. NOTE: this design-level issue potentially affects all products that use APOP, including (1) Thunderbird 1.x before 1.5.0.12 and 2.x before 2.0.0.4, (2) Evolution, (3) mutt, (4) fetchmail before 6.3.8, (5) SeaMonkey 1.0.x before 1.0.9 and 1.1.x before 1.1.2, (6) Balsa 2.3.16 and earlier, (7) Mailfilter before 0.8.2, and possibly other products.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://secunia.com/advisories/25402
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/25496
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/25529
Source: cve@mitre.org
Vendor Advisory
http://secunia.com/advisories/25546
Source: cve@mitre.org
Vendor Advisory
http://www.mozilla.org/security/announce/2007/mfsa2007-15.html
Source: cve@mitre.org
Patch Vendor Advisory
http://www.securityfocus.com/bid/23257
Source: cve@mitre.org
Patch
http://www.us-cert.gov/cas/techalerts/TA07-151A.html
Source: cve@mitre.org
US Government Resource
http://balsa.gnome.org/download.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://docs.info.apple.com/article.html?artnum=305530
Source: af854a3a-2127-422b-91ae-364da2661108
http://fetchmail.berlios.de/fetchmail-SA-2007-01.txt
Source: af854a3a-2127-422b-91ae-364da2661108
http://mail.gnome.org/archives/balsa-list/2007-July/msg00000.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25353
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25402
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/25476
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25496
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/25529
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/25534
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25546
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://secunia.com/advisories/25559
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25664
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25750
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25798
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25858
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/25894
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26083
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26415
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/35699
Source: af854a3a-2127-422b-91ae-364da2661108
http://security.gentoo.org/glsa/glsa-200706-06.xml
Source: af854a3a-2127-422b-91ae-364da2661108
http://sourceforge.net/forum/forum.php?forum_id=683706
Source: af854a3a-2127-422b-91ae-364da2661108
http://sylpheed.sraoss.jp/en/news.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.claws-mail.org/news.php
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1300
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2007/dsa-1305
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2007:105
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:107
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:113
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:119
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mandriva.com/security/advisories?name=MDKSA-2007:131
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.mozilla.org/security/announce/2007/mfsa2007-15.html
Source: af854a3a-2127-422b-91ae-364da2661108
Patch Vendor Advisory
http://www.novell.com/linux/security/advisories/2007_14_sr.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2009/08/15/1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2009/08/18/1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0344.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0353.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0385.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0386.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0401.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0402.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2009-1140.html
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/464477/30/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.securityfocus.com/archive/1/464569/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/470172/100/200/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/471455/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/471720/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/471842/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/23257
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
http://www.securitytracker.com/id?1018008
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.trustix.org/errata/2007/0019/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.trustix.org/errata/2007/0024/
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-469-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-520-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.us-cert.gov/cas/techalerts/TA07-151A.html
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.vupen.com/english/advisories/2007/1466
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1467
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1468
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1480
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1939
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/1994
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/2788
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2008/0082
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1231
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1232
Source: af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1424
Source: af854a3a-2127-422b-91ae-364da2661108

146 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
13.4%
94th percentile
Exploitation Status
Not in CISA KEV

Affected Vendors

apop_protocol